<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GoToMeeting Whitelist in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/373895#M428</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163514"&gt;@BillStrahan&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to successfully add the GoToMeeting executable to the allow list using any previous suggestions?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 17:19:40 GMT</pubDate>
    <dc:creator>gjenkins</dc:creator>
    <dc:date>2020-12-11T17:19:40Z</dc:date>
    <item>
      <title>GoToMeeting Whitelist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/365349#M392</link>
      <description>&lt;P&gt;Does anyone know how to whitelist the GoToMeeting download?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is an EXE but the client agent blocks it.&amp;nbsp; When I attempt to whitelist it, EVERY SINGLE download is a different hash value making it impossible to whitelist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any suggestions.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 20:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/365349#M392</guid>
      <dc:creator>BillStrahan</dc:creator>
      <dc:date>2020-11-24T20:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: GoToMeeting Whitelist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/365380#M393</link>
      <description>&lt;P&gt;Can you please post the alert details?&lt;/P&gt;&lt;P&gt;You can actually make an exception based on the filename, signer or various other methods etc.. under the Invetigation tab &amp;gt; Exclusions.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 21:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/365380#M393</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2020-11-24T21:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: GoToMeeting Whitelist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/367361#M413</link>
      <description>&lt;P&gt;Hi BillStrahan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be beneficial to post the "alert source" and "alert name" values observed when executing the GoToMeeting file. Adding to the allow list, &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/manage-file-execution.html" target="_self"&gt;as instructed here&lt;/A&gt;, would only work if the "Alert Source = 'XDR Agent'" and the "Alert Name contained 'malware.'"&amp;nbsp; Other alert sources and names have different instructions for creating exceptions to permit a file to run. For example, an alert with "Alert Source = 'XDR Agent'"&amp;nbsp;and the "Alert Name = 'Behavioral Threat,'" would need a BTP exception rather than a whitelist to permit execution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More information about the different ways to make exceptions can be found here: &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile.html" target="_self"&gt;Add a New Exceptions Security Profile&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let us know your findings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS. Given that the hash changes frequently, there are two other ways to permit the GoToMeeting file to run if it is being categorized as malware, and that is by adding the signer to the Allow List Signers ('Malware Security Profile' &amp;gt; 'Allow List Signers,') or to a Files/Folders allow list ( 'Malware Security Profile' &amp;gt; 'Files/Folders in Allow List.')&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 18:26:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/367361#M413</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2020-12-04T18:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: GoToMeeting Whitelist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/367544#M418</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163514"&gt;@BillStrahan&lt;/a&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For this very "installer," the Trusted Publisher feature was introduced over 4 years ago.&amp;nbsp; The Trusted Publisher feature should allow the installer to run.&amp;nbsp; I recommend contacting Support if you are seeing blocks tied to the GTM installer.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 18:47:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/367544#M418</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-12-06T18:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: GoToMeeting Whitelist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/367850#M419</link>
      <description>&lt;P&gt;Our prior AV solution began having fits with Goto products about a year ago.&amp;nbsp; As paying customers we begged the LogMeIn vendor to stop changing the hash of the file each time it was downloaded to no avail.&amp;nbsp; We were forced to place the vendors certificate on the allow list since this crippled the organization.&amp;nbsp; We have not run into any issues with the Goto products with Cortex XDR Prevent 7.1.3 on Windows (don't do Mac/Linux).&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/367850#M419</guid>
      <dc:creator>EddieRowe</dc:creator>
      <dc:date>2020-12-08T16:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: GoToMeeting Whitelist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/373895#M428</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163514"&gt;@BillStrahan&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to successfully add the GoToMeeting executable to the allow list using any previous suggestions?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 17:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/gotomeeting-whitelist/m-p/373895#M428</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2020-12-11T17:19:40Z</dc:date>
    </item>
  </channel>
</rss>

